Category: News

  • OpenAI said its AI “hacked” Hugging Face last week.

    OpenAI said its AI “hacked” Hugging Face last week.

    I went and looked. OpenAI is a verified enterprise organization on Hugging Face — 135 team members, models hosted there, a dataset published that same week.

    That’s not a locked door. That’s a tenant.

    Nobody picked a lock. Somebody badged in.

    And this isn’t new:

    → 2001 — a British man reached 97 U.S. military and NASA computers by scanning for blank administrator passwords. They called it “the biggest military hack of all time.”
    → 2023 — attackers walked into MGM Resorts by phoning the help desk.
    → 2026 — an AI reached a company it already held 135 seats inside.

    Three “hacks.” Three open doors. The vocabulary keeps outrunning the intrusion.

    Here’s the uncomfortable part: containment isn’t hard. chroot shipped in 1979 — six years before Sam Altman was born. gVisor, Firecracker microVMs, default-deny egress — commodity, documented, free. The test environment simply had a door to the open internet and a live credential sitting next to it.

    We are running 2026 agents on 1998 authentication.

    So here’s the gauntlet, @OpenAI / @Hugging Face: send us the logs. Free, public, one week. We’re a small shop in Orange County with no vendor to protect and no narrative to defend, and we’ll read them straight. You won’t — you don’t need to. The answer’s already on your own profile page.

    Full four-page assessment attached — sent the only way that felt appropriate.

    (Yes, it’s a fax. On purpose. It’s about as modern as the auth most AI companies are protecting their models with.)

    #cybersecurity #AI #infosec #vCISO

Exit mobile version